Papalocal
Loading…
Papalocal Your local communities & everything app — businesses, deals, library, and more.

How GDPR's Standard Contractual Clauses Work and Why They're Under Legal Scrutiny

The legal mechanism that lets EU companies send personal data abroad—and the court rulings that have put it in jeopardy.

By Garret Merkley · Explainer · Jun 13, 2026
Branched from Understanding Data Residency and Data Localization Requirements in Cloud Computing
Quick take
  • Standard Contractual Clauses (SCCs) are pre-approved legal templates that let companies transfer EU personal data to countries without equivalent privacy laws.
  • The EU Court of Justice has twice ruled SCCs inadequate without additional safeguards, citing US surveillance practices and lack of recourse.
  • Companies using SCCs must now conduct Transfer Impact Assessments and often add technical measures like encryption to comply with recent rulings.

Standard Contractual Clauses are legally binding contract templates approved by the European Commission. They're designed to bridge a specific gap: GDPR forbids sending personal data outside the EU unless the destination country has equivalent privacy protections. Most countries don't. SCCs work by having the data exporter (say, a German company) and the data importer (a US cloud provider) both agree in writing that they'll treat the data as if GDPR rules still apply—even though they're outside the EU's legal reach. Think of them as a contractual promise to maintain EU-level privacy standards in a foreign jurisdiction.

How SCCs Actually Function

The European Commission publishes standard SCC templates. A company doesn't negotiate them from scratch; it adopts the approved wording almost verbatim. The clauses commit both parties to specific obligations: the importer must not process the data for its own purposes, must implement security measures, must honor data subject rights (like access and deletion), and must allow audits. Critically, the exporter remains liable to the data subject if the importer breaches GDPR—so a German HR department sending employee records to a US payroll vendor is legally responsible if that vendor leaks them, even though the vendor is outside EU jurisdiction.

SCCs also include a 'onward transfer' clause: if the US vendor needs to hire a subcontractor in India, that subcontractor must sign the same SCC terms. This creates a chain of contractual promises, though each link depends on the previous one's enforceability—a key vulnerability courts have flagged.

Why Courts Have Repeatedly Rejected Them

In July 2020, the EU Court of Justice (CJEU) invalidated the Privacy Shield framework, which had been the primary legal basis for US-EU data transfers. The ruling didn't kill SCCs outright, but it exposed a fatal flaw: a contract between two private companies cannot override a foreign government's surveillance laws. The court found that US intelligence agencies—under laws like FISA Section 702—can access data held by US companies with minimal judicial oversight, and data subjects have no meaningful recourse. A contractual promise to keep data private is worthless if the US government can legally demand and access it anyway.

In October 2022, Austria's data protection authority took this further, ruling that SCCs alone are insufficient for transfers to the US. The CJEU upheld this position in June 2023 (in the Meta Ireland case), emphasizing that companies must conduct a 'Transfer Impact Assessment'—essentially proving that the destination country's legal framework, combined with contractual and technical safeguards, provides adequate protection. The court made clear: SCCs are a baseline, not a complete solution.

What 'Transfer Impact Assessment' Actually Means

After the 2023 ruling, companies can no longer simply sign an SCC and assume they're compliant. They must now document an assessment that includes: the laws of the destination country (do they allow mass surveillance? is there judicial review?), the specific data being transferred (is it sensitive?), the importer's actual practices (do they encrypt? do they limit access?), and supplementary technical measures (encryption, pseudonymization, access controls). If the assessment shows gaps—for instance, that US surveillance laws are too broad and encryption won't help—the company may need to either refuse the transfer, add more safeguards, or stop processing that data altogether.

Why This Matters and When It Applies

SCCs affect any company in the EU that uses a non-EU service provider—cloud storage, payroll software, CRM tools, analytics platforms. If you're a French e-commerce company using a US-based email marketing platform, you're transferring customer email addresses and purchase history via SCC. The legal scrutiny matters because courts have signaled that SCCs alone won't survive future challenges, especially for transfers to countries with aggressive surveillance laws. The practical effect: companies face either higher compliance costs (adding encryption, restricting data, conducting detailed assessments) or withdrawal from certain markets. Data protection authorities are now actively investigating SCC usage, and fines for non-compliance can reach 4% of global revenue under GDPR.

The Current State of Play
  • SCCs are still legally valid and widely used, but no longer a 'set it and forget it' solution.
  • Companies must document a Transfer Impact Assessment for each transfer and update it if laws or circumstances change.
  • Many organizations are adding technical safeguards like end-to-end encryption to reduce reliance on SCCs alone.
  • Some EU regulators are now questioning whether SCCs can ever be sufficient for US transfers given US surveillance law.
Can I still use Standard Contractual Clauses after the 2023 court ruling?
Yes, but only as part of a broader compliance package. You must conduct a Transfer Impact Assessment, document it, and often add technical safeguards. SCCs alone are no longer sufficient.
What happens if I transfer data without an SCC or adequate assessment?
You're violating GDPR Article 44. Data protection authorities can issue warnings, fines up to 4% of global revenue, or orders to stop the transfer. You're also liable to data subjects for any harm.
Does my SCC need to be updated after the 2023 ruling?
Not necessarily the SCC itself—the templates remain unchanged. But your documentation and assessment must be updated to reflect the new legal standard that SCCs alone are insufficient.
Are there alternatives to SCCs for transferring data outside the EU?
Yes: Binding Corporate Rules (BCRs) if you're a multinational with multiple entities, or adequacy decisions if the destination country has been formally approved by the EU (very few exist—only about 15 countries qualify).
If I encrypt data before transferring it, does that solve the SCC problem?
Encryption helps but doesn't eliminate the problem entirely. If the importer holds the encryption keys or can access unencrypted data during processing, encryption doesn't provide complete protection. It's a supplementary measure, not a replacement for SCCs.

Sources